CVE Tools

Poppler

125 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Poppler, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Poppler CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Poppler CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-043
2025-050
2025-060
2025-071
2025-082
2025-090
2025-102
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-094

Severity

How the 125 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical76%
  • High3830%
  • Medium7762%
  • Low32%

Latest CVEs

The 15 most recently published vulnerabilities affecting Poppler.

  1. CVE-2026-93314Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow6.3
  2. CVE-2026-93313Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow6.3
  3. CVE-2026-93312Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference4.3
  4. CVE-2026-93311Freedesktop Poppler SampledFunction Function.cc integer overflow4.3
  5. CVE-2025-52885GHSL-2025-042: Poppler has Use-After-Free7.3
  6. CVE-2025-43718Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expr...2.9
  7. CVE-2025-50422Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.2.9
  8. CVE-2025-50420An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).6.5
  9. CVE-2025-52886Poppler Use After Free Vulnerability5.9
  10. CVE-2025-43903NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.4.3
  11. CVE-2025-32364A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.4.0
  12. CVE-2025-32365Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.4.0
  13. CVE-2024-56378libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.4.3
  14. CVE-2024-6239Poppler: pdfinfo: crash in broken documents when using -dests parameter7.5
  15. CVE-2022-37051An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store